High severity7.7NVD Advisory· Published Mar 6, 2026· Updated Jul 15, 2026
CVE-2026-26017
CVE-2026-26017
Description
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of-Use (TOCTOU) flaw. This issue has been patched in version 1.14.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/coredns/corednsGo | < 1.14.2 | 1.14.2 |
Affected products
25- osv-coords23 versionspkg:apk/chainguard/eks-distro-coredns-1.31pkg:apk/chainguard/eks-distro-coredns-1.32pkg:apk/chainguard/eks-distro-coredns-1.33pkg:apk/chainguard/eks-distro-coredns-1.34pkg:apk/chainguard/eks-distro-coredns-1.35pkg:apk/chainguard/eks-distro-coredns-fips-1.31pkg:apk/chainguard/eks-distro-coredns-fips-1.32pkg:apk/chainguard/eks-distro-coredns-fips-1.33pkg:apk/chainguard/eks-distro-coredns-fips-1.35pkg:apk/chainguard/juicefs-1.2pkg:apk/chainguard/juicefs-1.3pkg:apk/chainguard/k8s_gatewaypkg:apk/chainguard/k8s_gateway-fipspkg:apk/chainguard/kubernetes-dns-node-cachepkg:apk/chainguard/kubernetes-dns-node-cache-fipspkg:apk/wolfi/juicefs-1.3pkg:apk/wolfi/k8s_gatewaypkg:apk/wolfi/kubernetes-dns-node-cachepkg:golang/github.com/coredns/corednspkg:rpm/opensuse/coredns&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/coredns&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 1.31.43-r2+ 22 more
- (no CPE)range: < 1.31.43-r2
- (no CPE)range: < 1.32.35-r1
- (no CPE)range: < 1.33.25-r1
- (no CPE)range: < 1.34.17-r2
- (no CPE)range: < 1.35.7-r1
- (no CPE)range: < 1.31.43-r2
- (no CPE)range: < 1.32.35-r1
- (no CPE)range: < 1.33.25-r1
- (no CPE)range: < 1.35.7-r1
- (no CPE)range: < 1.2.5-r7
- (no CPE)range: < 1.3.1-r8
- (no CPE)range: < 1.6.4-r2
- (no CPE)range: < 1.6.4-r3
- (no CPE)range: < 1.26.7-r9
- (no CPE)range: < 1.26.7-r11
- (no CPE)range: < 1.3.1-r8
- (no CPE)range: < 1.6.4-r2
- (no CPE)range: < 1.26.7-r9
- (no CPE)range: < 1.14.2
- (no CPE)range: < 1.14.2-bp160.1.1
- (no CPE)range: < 1.14.2-1.1
- (no CPE)range: < 0.0.20260317T205859-150000.1.152.1
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
10- github.com/advisories/GHSA-c9v3-4pv7-87prghsaADVISORY
- github.com/coredns/coredns/security/advisories/GHSA-c9v3-4pv7-87prnvdMitigationVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-26017ghsaADVISORY
- github.com/coredns/coredns/releases/tag/v1.14.2nvdProductRelease NotesWEB
- access.redhat.com/errata/RHSA-2026:25127nvd
- access.redhat.com/errata/RHSA-2026:36873nvd
- access.redhat.com/errata/RHSA-2026:8151nvd
- access.redhat.com/security/cve/CVE-2026-26017nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26017.jsonnvd
News mentions
0No linked articles in our index yet.